CVE-2026-102805 Details
Description
A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be executed remotely. The exploit has been published and may be used.
A vulnerability has been identified in the Nothings STB image writing library, specifically in versions of 'stb_image_write.h' prior to 1.16. The issue arises from the 'stbi_write_png_to_mem', 'stbi_write_jpg_core', and 'stbi_write_tga_core' functions, where size calculations using 'int' arithmetic can overflow when handling large images. This overflow leads to memory corruption by either truncating values or creating negative offsets, which can be exploited remotely. The vulnerability causes a heap buffer overflow during PNG encoding and out-of-bounds reads in JPEG and TGA encoding.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nothings/stb/ | [email protected] | Vendor |
| https://github.com/nothings/stb/issues/1964 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/nothings/stb/issues/1964#issuecomment-5404606996 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/cve/CVE-2026-102805 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/944868 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/411497 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/411497/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-189 | Numeric Errors | [email protected] |
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Nothings stb_image_write | <= 1.16 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion